- Disable auditing
- Grab password file
- Create and “adminkit”
- Enumerate server information
- Enumerate secrets of LSA
- Dump Registry info
- Use Nltest
- Pilfer the box
- Add an administrator account
- Grab a remote command shell
- Hijack the GUI
- Disable Passprop
- Install a back door
- Install Trojan horses and sniffers
- Repeat
- Hid the adminkit
- Enable auditing
Posted inCheat Sheets